Prevention model · Whistleblowing channel · Corporate criminal defence
From the risk analysis to defence in court if it ever comes to that. We design, implement and maintain criminal compliance programmes tailored to the reality of each company.
Since the 2015 reform of the Spanish Criminal Code, legal entities — companies, associations, foundations — can be held criminally liable for offences committed by their directors, managers or employees in the name and for the benefit of the company.
The penalties for legal entities are severe: fines of up to twice the profit obtained, dissolution of the company, suspension of activities for up to 5 years, and bans on contracting with the public sector or receiving grants.
However, the same Article 31 bis provides that the company is exempt from liability — or the penalty is significantly reduced — if it has adopted and effectively implemented an organisation and management model that prevents these offences.
Criminal compliance is not just an obligation for large corporations. Any company — including SMEs and self-employed professionals operating through a company — is subject to the corporate criminal liability regime.
If the company has an effective prevention model and the offence is committed by circumventing its controls, the company may be exempt from criminal liability.
A well-implemented compliance programme builds an internal culture of integrity that reduces workplace disputes and protects the company's reputation.
Many public contracts and grant programmes require proof that the company has no criminal convictions. Compliance reduces that risk.
Companies with solid compliance programmes inspire greater confidence in due diligence processes, investment rounds and commercial relationships with large clients.
The Spanish Criminal Code sets out a closed list of offences that can trigger criminal liability for legal entities. These are the most common in mid-sized companies and SMEs:
Defrauding the Spanish tax authority (Hacienda) or Social Security. It is one of the most common economic offences and carries the highest reputational risk.
Especially relevant in the real estate, financial, advisory and international trade sectors. Anti-money-laundering regulations impose specific obligations.
Payments or benefits given to executives of other companies to win contracts or favourable decisions. A real risk in companies with active sales teams.
GDPR breaches that lead to the unlawful use of personal data, unauthorised access or disclosure of confidential information about clients or employees.
Imposing working conditions that infringe employees' rights, or workplace or sexual harassment within the company without preventive measures in place.
Pollution of soil, water or the atmosphere through discharges or emissions. Manufacturing, construction and logistics businesses have high exposure.
There is no one-size-fits-all model. Compliance must be tailored to the activity, size, structure and specific risks of each organisation. This is how we work.
We analyse the company's activity, its organisational structure, key processes and the criminal risks specific to its sector. Interviews with management and key departments.
We identify and assess the specific criminal risks the company is exposed to: likelihood, impact and existing controls. This is the foundation of the model.
We draft the Organisation, Management and Control Model: policies, procedures, code of ethics, whistleblowing channel, compliance body and response protocols.
Training sessions for employees and management, adapted to each level. The model is only effective if the people in the organisation know it and apply it.
Compliance is not a document to be filed away. We carry out regular reviews to adapt the model to regulatory, organisational or business changes.
If the answer is no — or if you are not sure whether the one you have is robust enough — it is time to talk to us. The first consultation is free and comes with no obligation.